Back to Blog
Compliance
4 min read

PIPEDA Compliance: What Canadian Businesses Actually Have to Do

Ten principles, a breach register almost nobody keeps, and the question of whether PIPEDA even applies to you. A practical read of the federal privacy law.

GuardsArm Team

Security Experts

September 25, 2026

PIPEDA compliance for Canadian businesses

Most Canadian organisations treat PIPEDA as a privacy policy on the website and leave it there. The policy is the smallest part of it. The parts that generate findings are the accountability structure behind the policy, the breach register nobody is keeping, and a scope question many organisations answer wrongly in their own favour.

Scope is misjudged
Provincial laws do not displace PIPEDA for cross-border or federally regulated activity
Three breach duties
Report, notify, and record — the record-keeping one is most often missed
Records run 24 months
Every breach, not only the reportable ones

First: does it apply to you?

PIPEDA governs personal information collected, used or disclosed in the course of commercial activity. Three provinces — Quebec, British Columbia and Alberta — have private-sector laws declared substantially similar, so within those provinces their law generally governs local commercial activity instead.

That exemption is narrower than people assume. PIPEDA still reaches you if:

SituationPIPEDA applies
Federally regulated business (bank, telecom, airline, inter-provincial transport)Yes, wherever you operate
Personal information crossing a provincial border in commercial activityYes
Personal information crossing the national borderYes
Employee data, federally regulated employerYes
Employee data, provincially regulated employerNo — provincial law, or nothing

A BC company with customers in Ontario is not in a single-regime world. See operating across provinces.


The ten principles, grouped by what they cost you

Schedule 1 lists ten fair information principles. They are not equally demanding in practice.

The ten principles by practical difficultyAccountability, limiting collection and safeguards are where findings come from. Consent, purpose and accuracy are usually covered by the privacy notice. Openness, access and challenging compliance are process obligations.AccountabilityA named individual, resourced — not a title on a policyLimiting collection, use, retentionWhere most organisations are quietly offsideSafeguardsScaled to sensitivity; maps to your security programmeConsent, purpose, accuracyUsually handled adequately by the privacy noticeOpenness, access, challenging complianceProcess obligations — cheap once a process exists
Two of the three hard ones are about restraint, not protection.

Accountability is the one with teeth. You must designate an individual responsible for compliance, and that person's name has to be available on request. In smaller organisations this is often assigned and then never resourced — which is exactly what an investigation surfaces.

Limiting collection, use and retention is where most organisations are quietly offside. Data collected for one purpose gets reused for another, and retention schedules either do not exist or are not enforced by anything technical.

Safeguards is the principle a security assessment maps to directly, and the only one where the wording explicitly scales protection to the sensitivity of the information.


The breach obligations, in the order they bite

Since November 2018 breach reporting has been mandatory. There are three distinct duties and organisations routinely satisfy only the first two.

The PIPEDA breach sequenceContain the exposure, assess whether there is a real risk of significant harm, report to the Privacy Commissioner of Canada, notify affected individuals, and record every breach for twenty-four months.Containstop the exposureAssessreal risk of significant harm?Reportto the Privacy CommissionerNotifyaffected individualsRecordevery breach, 24 months
The last step applies to breaches that fail the harm threshold too.

The threshold for reporting and notifying is a real risk of significant harm — assessed on the sensitivity of the information and the probability of misuse. Significant harm is broadly drawn: humiliation, damage to reputation or relationships, identity theft, financial loss, loss of employment or professional opportunity.

The register covers every breach, not just the reportable ones
Organisations record the incidents they reported and nothing else. The obligation is to keep a record of every breach of security safeguards for 24 months and produce them to the Commissioner on request. An empty register at a large organisation is not evidence of a clean year; it reads as evidence that nobody was looking.

That register is the cheapest compliance win available. It is a spreadsheet with a row per incident, and its absence is an offence in itself.


What to fix first

Ranked by how often it is missing and how quickly it can be closed:

  1. Name the accountable individual and give them a budget line
  2. Start the breach register today, backdated as far as your records allow
  3. Write down a retention schedule and enforce at least one part of it technically
  4. Map where personal information crosses a border — provincial or national
  5. Run a risk assessment against the safeguards principle, not against a generic checklist

Transfers to a processor are not disclosures requiring fresh consent, but accountability travels with the data: you remain answerable for what your processor does, and contractual protection comparable to your own is the mechanism. That makes vendor risk assessment a PIPEDA obligation rather than a nice-to-have.


What an OPC investigation actually asks for

The Commissioner operates an ombudsman model: findings and recommendations rather than fines. That shapes what an investigation feels like. Rather than calculating a penalty, the office establishes what happened and whether your practices meet the principles, then publishes a finding.

What gets requested, near-universally:

  • The name and role of your accountable individual, and evidence they were actually exercising the function
  • Your retention schedule, and evidence it was applied to the data in question
  • The risk assessment behind your safeguards — not a statement that they were reasonable, but the reasoning
  • Your breach register, in full
  • Contracts with any processor involved, showing comparable protection

Organisations that struggle are rarely the ones with weak technology. They are the ones that made sound decisions without recording why, and cannot reconstruct the reasoning a year later.


GuardsArm runs PIPEDA gap assessments and builds the accountability and breach machinery behind them. See PIPEDA compliance services or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.